*** Unsent and unapproved draft ***


About the Apache Software Foundation

The ASF is a US 501(c)3 non-profit charity that acts as a steward for several hundred open source projects. The ASF is one of the largest open source organizations in the world, and is home to prolific projects such as Apache Hadoop, Apache Tomcat, Apache Cassandra, and scores of others. The ASF provides a known and vetted set of governance, intellectual property, and release processes as well as providing a vendor-neutral place for contributors to collaborate. However, within those processes there is a high degree of autonomy for each project. Projects decisions are driven by the people doing the work. The ASF Board of Directors is responsible for project oversight, ensuring the health and vitality of each project. 

In brief numbers the ASF has: 

How the ASF keeps our projects secure

About the recent issues in log4j

Before jumping directly into recommendations, it is worth describing the factors contributing to the recent log4j vulnerability.  Our recommendations are based on those experiences as well as over 20 years of dealing with vulnerabilities in open source software.

Recommendations

These experiences inform our positions on a number of items.

The incentive has to be some form of liability (civil and/or criminal) if a system owner does any of the above. Such liability may already exist, for example in the FTC. Expanding the funding of the organizations tasked with enforcement in one possible option

Further reading